If attacker (while chatting) will try to upload specially crafted file with name: c"><img src="a" onerror="alert(document.cookie)">hh.jpg - then operator would get javascript code execution without any interaction.